Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 642f49bd4041f800…

MALICIOUS

RTF / .DOC

10.0 KB
MD5: 947aae10512ef00d58502adca5bf344c SHA-1: 2860ef4a0b1a9c0269358cb159cb0ad03f438c88 SHA-256: 642f49bd4041f800c81be184ca3e15a011f287d68345d8e0b6299367cd21e445
62 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.001 Spearphishing Attachment

The RTF document contains a critical heuristic firing for remote template injection, pointing to a specific URL. This indicates the file is designed to load external content, likely malicious, from the specified address. The document body discusses 'soft violence' and media manipulation, which may be a lure or distraction, but the primary technical finding is the remote template injection.

Heuristics 2

  • Remote template injection (\*\template → remote URL) critical CVE related RTF_REMOTE_TEMPLATE
    The RTF's \*\template destination is a remote URL/UNC path. When Word opens the document it fetches and loads that template, which can carry macros or an exploit, deliver a scriptlet/HTA, or leak NTLM credentials over UNC. Benign documents attach only a local template, so a remote \*\template target is template-injection delivery (MITRE T1221). remote \*\template target (Word fetches it on open); dynamic-DNS / abuse-prone host; target is active/script content, not a .dot template.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://solmo.twilightparadox.com/0abadf7f46c01536d880809f62a274c9f48b01d7/0045321060300.html